CVE-2016-1623Google Chrome vulnerability

CWE-2648 documents6 sources
Severity
8.8HIGHNVD
EPSS
1.5%
top 18.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 14

Description

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to FrameLoader.cpp, HTMLFrameOwnerElement.h, LocalFrame.cpp, and WebLocalFrameImpl.cpp.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDgoogle/chrome48.0.2564.103

Also affects: Debian Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-3r93-h67f-8rhp: The DOM implementation in Google Chrome before 482022-05-14
OSV
oxide-qt vulnerabilities2016-02-18
OSV
CVE-2016-1623: The DOM implementation in Google Chrome before 482016-02-13

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-02-18
Red Hat
chromium-browser: same-origin bypass in DOM2016-02-09

💬Community

2
Bugzilla
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function2016-04-12
Bugzilla
CVE-2016-1623 chromium-browser: same-origin bypass in DOM2016-02-10